Cookie Policy
Cookies, sessions, and local signal storage.
This page lists the cookies and browser storage VibeForge actually uses for analytics, attribution, anonymous forge metering, email sessions, Lyrics Generator context, Pro access, and Stripe checkout.
Last updated July 20, 2026
How VibeForge uses cookies and storage
VibeForge uses a small amount of browser storage to keep the app fast, remember basic access state, meter the first 5 lifetime free forges, pass Vibe Board context into the Lyrics Generator, measure product usage, and support checkout. The cookie banner is informational and non-blocking so the prompt builder remains usable.
VibeForge storage we set
- vibeforge_email in localStorage: remembers the email you entered for signup, copy unlock, or Pro status checks so you do not need to retype it every visit.
- vibeforge_email_session cookie: a 90-day HttpOnly, SameSite=Lax email session cookie used by server routes to check Pro entitlement and saved profile access.
- vibeforge_anon_session cookie: a signed, HttpOnly, SameSite=Lax anonymous identifier minted by VibeForge server routes to meter the first 5 lifetime free copy/export forges without trusting request-body email or localStorage.
- vibeforge_saved in localStorage: stores free saved Vibe Profiles and browser-only prompt builder saves on your device.
- vibeforge_lyrics_context in sessionStorage: temporarily passes your current Vibe Board context, email access state, and production prompt details into the Lyrics Generator workspace. It is not a server-side lyric draft store.
- vibeforge_attribution in localStorage and a first-party cookie: stores UTM campaign fields for up to 30 days so signup and checkout events can be attributed to ad campaigns.
- vibeforge_cookie_consent in localStorage: remembers that you dismissed the cookie banner.
Analytics cookies and identifiers
- VibeForge loads the NanoCorp/PostHog analytics script to capture page views, SPA route changes, clicks, JavaScript errors, and Core Web Vitals.
- PostHog analytics may use cookies or localStorage identifiers to understand anonymous sessions and product usage over time.
- Lyrics Generator analytics may include the selected language, language label, generation or export event type, section counts, theme text when supplied, and high-level control metadata so we can improve multi-language workflows.
- We use analytics to improve the Vibe Board and Lyrics Generator, measure campaign performance, diagnose bugs, and avoid shipping slow or confusing pages.
Authentication and Pro access
- The signed vibeforge_email_session cookie lets server routes verify the email associated with a Pro entitlement without exposing the raw session logic to client scripts.
- Pro saved profiles are stored server-side with your email lead record. Free prompt saves stay in your browser unless you choose to upgrade or save through a Pro feature. Current lyric drafts are not saved as server-side account projects in the current build.
- Clearing cookies, localStorage, or sessionStorage may sign you out of email-based access, rotate the anonymous forge-metering identity, remove local prompt saves, clear Lyrics Generator context, and require you to enter your email again. Existing server-side forge events tied to an email account stay associated with that account after signup/login, but a brand-new browser with no VibeForge cookies can start a new anonymous identity.
Stripe checkout
- VibeForge sends Pro buyers to a NanoCorp-hosted Stripe checkout page. Stripe may set checkout, fraud-prevention, and payment-security cookies on the checkout domain.
- VibeForge receives payment status events needed to activate Pro, but Stripe handles card numbers and sensitive payment credentials.
- Do not enter Stripe test-card numbers on live checkout links; test cards work only on dedicated test checkout links shared for testing.
Your controls
- You can clear VibeForge localStorage, sessionStorage, and cookies from your browser settings to remove local identifiers, saved prompts, Lyrics Generator context, attribution values, anonymous forge identity, and banner acknowledgement.
- You can block or limit third-party cookies in your browser. Some analytics, attribution, checkout, or session behavior may become less accurate.
- For privacy or deletion requests related to stored email, Pro entitlement, saved profile data, or Lyrics Generator usage records, contact vibeforge@nanocorp.app.